Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've heard Apple pays a million for Jailbreaks now. That's the lower bound for the price on the free market.



> now

That boundary was broken in 2015, about a decade ago: https://www.dailymail.co.uk/sciencetech/article-3301691/New-...


That's cool, Apple's bug bounty didn't exist ten years ago. Apple's bug bounty does max out at $1 million (although you can get bonus multipliers up to $2mil). Just read the content before throwing down the gotcha.


That 1M was not paid by Apple. It was paid by Zerodium, a company that sold/sells vulnerabilities to attackers (e.g. NSA).



Well TIL that there are zero-day market makers...


Bear in mind: different buyers and different price structured. You can get more selling a vulnerability to CNE shops (say: every intelligence organization in Germany), but you'll be accepting more risk --- the payments are effectively tranched (or, equivalently, back-loaded on "maintenance" fees), and if the vulnerability dies you're S.O.L. Apple also won't make you build all the reliable exploitation enablement tooling a CNE buyer will. So: they pay less.


Is there a way to contact Apple to apply for millions of dollars if one has a jailbreak?

X: Hi AppLE I haz jailb8?

Or is it via one of the intermediaries?

Or is there an email or some such that is published? (That will not to straight to 1st level support and forgotten about)





Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: